Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesHard

A financial institution uses Azure DevOps for its mission-critical applications. They have a complex release pipeline with multiple stages (Dev, QA, Staging, Production). Due to regulatory compliance, every deployment to the Production environment must be explicitly approved by two different senior managers. Additionally, if the deployment fails in Production, an automated incident management system must be triggered. How should the team configure the Production stage to meet these requirements?

  1. AConfigure 'Pre-deployment approvals' requiring two specific users and 'Post-deployment gates' for invoking an Azure Function that triggers the incident system.
  2. BImplement a custom approval workflow using Azure Logic Apps and set up a conditional task for incident triggering in the pipeline.
  3. CAdd a manual intervention task before the deployment and a custom script task after deployment for incident triggering.
  4. DUse 'Post-deployment approvals' for the managers and add a 'Run on failure' task to trigger the incident system.
Show answer & explanation

Correct answer: A. Configure 'Pre-deployment approvals' requiring two specific users and 'Post-deployment gates' for invoking an Azure Function that triggers the incident system.

Pre-deployment approvals directly support requiring specific users to approve a deployment before it starts. Post-deployment gates, specifically invoking an Azure Function, are ideal for automated actions like triggering an incident management system based on deployment status (success or failure) and are executed after the deployment process finishes, allowing for evaluation of the deployed system's health.

Why the other options are wrong

  • B. While Logic Apps could be part of a custom solution, Azure DevOps has built-in features (approvals/gates) that are more direct and integrated for this scenario.
  • C. Manual intervention tasks are for pauses during deployment, not for formal pre-deployment approvals. A custom script task isn't the most robust way to trigger an incident system based on deployment status.
  • D. Post-deployment approvals would mean the deployment happens before approval, which violates the 'every deployment to Production must be explicitly approved' requirement. 'Run on failure' is a task condition, but a post-deployment gate provides more control and integration for external systems based on overall stage status.

Pre/Post-Deployment Gates

Automated validations or manual approvals that run before or after a stage in an Azure DevOps release pipeline, controlling the flow of releases.

  • Pre-deployment gates/approvals run before a stage starts.
  • Post-deployment gates/approvals run after a stage completes.
  • Can integrate with external systems for automated checks or trigger actions.

Memory trick: Approve BEFORE, alert AFTER if it fails.

More Design and implement pipelines questions